<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>AWS — Things Worth Sharing</title><description>Bài viết gắn tag AWS.</description><link>https://cloudsecop.net/</link><item><title>Remote SWE agents: autonomous coding với AWS Strands Agents</title><link>https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</guid><description>AWS Strands Agents + Bedrock AgentCore cho autonomous SWE agent. GitHub issue → PR. Threat model, IAM blast radius, audit. So sánh Copilot Workspace và Devin.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>AWS</category><category>Bedrock</category><category>AI Agents</category><category>DevOps</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>Migration AWS/Vercel sang Cloudflare: playbook thực tế</title><link>https://cloudsecop.net/blog/migration-aws-to-cloudflare/</link><guid isPermaLink="true">https://cloudsecop.net/blog/migration-aws-to-cloudflare/</guid><description>Playbook migrate production từ AWS (Lambda, DynamoDB, RDS, S3, SQS, ElastiCache) sang Cloudflare: mapping primitive, 3 chiến lược, data migration, cutover, rollback, 10 pitfall.</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Migration</category><category>AWS</category><category>Serverless</category><author>KhaVan</author></item><item><title>Cost model Cloudflare Developer Platform: tier, so sánh AWS</title><link>https://cloudsecop.net/blog/cost-model-production/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cost-model-production/</guid><description>Pricing từng primitive Cloudflare (Workers, D1, KV, R2, Queues, DOs, Vectorize, Workers AI), breakpoint, so sánh AWS, 3 scenario: blog, SaaS 10k user, app 100M req/tháng.</description><pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare Developer</category><category>Cost</category><category>AWS</category><category>Pricing</category><author>KhaVan</author></item><item><title>MCP server: Cloudflare Workers vs AWS Bedrock AgentCore — chọn cái nào</title><link>https://cloudsecop.net/blog/mcp-server-cloudflare-vs-bedrock-agentcore/</link><guid isPermaLink="true">https://cloudsecop.net/blog/mcp-server-cloudflare-vs-bedrock-agentcore/</guid><description>So sánh MCP server Cloudflare (Workers + R2/D1/KV, OAuth) với AWS Bedrock AgentCore (IAM, dài-hạn). Latency, cost, auth, kịch bản dùng — và tôi chọn cái nào.</description><pubDate>Sun, 30 Nov 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AWS</category><category>MCP</category><category>AI Agents</category><author>KhaVan</author></item><item><title>AWS Well-Architected custom lens: build riêng cho cloud security ở scale</title><link>https://cloudsecop.net/blog/aws-well-architected-custom-lens/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-well-architected-custom-lens/</guid><description>Custom lens AWS Well-Architected: thêm pillar riêng cho org, JSON schema, deploy CloudFormation, attach workload. Use case Vietnam compliance Circular 09, Decree 53.</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Governance</category><category>Well-Architected</category><category>Architecture</category><author>KhaVan</author></item><item><title>AWS Security Services Best Practices: đọc cuốn cẩm nang mới</title><link>https://cloudsecop.net/blog/aws-security-services-best-practices/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-services-best-practices/</guid><description>AWS vừa publish best-practices guide cho 10 dịch vụ bảo mật (GuardDuty, Security Hub, Macie, Inspector, WAF, Network Firewall). Cấu trúc guide và lộ trình triển khai thực tế.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Hub</category><category>Best Practices</category><author>KhaVan</author></item><item><title>AWS Security Maturity Model v2: 4 phase áp dụng thực tế</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-v2/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-v2/</guid><description>AWS Security Maturity Model v2: 74 kiểm soát chia 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized), thứ tự nên làm, bẫy thường gặp, ánh xạ vào Organization.</description><pubDate>Sun, 27 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Bedrock từ Workers qua OIDC federation — case study production</title><link>https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</link><guid isPermaLink="true">https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</guid><description>Worker mint RS256 JWT → STS AssumeRoleWithWebIdentity → Bedrock Claude Opus. Số liệu thực: token 5ms, STS 200ms, Bedrock 2-3s, cached 50ms.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AWS</category><category>Bedrock</category><category>OIDC</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>AWS SMM Assessment Tool: đánh giá posture trong một chiều</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</guid><description>Ghi chú dùng AWS Security Maturity Model Assessment Tool đánh giá posture theo 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized): kiến trúc, quy trình, JSON/Excel.</description><pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Assessment</category><category>Governance</category><author>KhaVan</author></item><item><title>hardeneks: EKS security checks ở CI vs sau-deploy</title><link>https://cloudsecop.net/blog/hardeneks-eks-security/</link><guid isPermaLink="true">https://cloudsecop.net/blog/hardeneks-eks-security/</guid><description>hardeneks là Python CLI chạy 100+ EKS best-practice check. Lý do tôi chạy ở PR thay vì weekly cron, so sánh kube-bench/kube-hunter, finding thực tế.</description><pubDate>Wed, 04 Jun 2025 00:00:00 GMT</pubDate><category>AWS</category><category>EKS</category><category>Kubernetes</category><category>Cloud Security</category><category>Compliance</category><author>KhaVan</author></item><item><title>Cloudflare Access vs AWS IAM Identity Center cho team admin</title><link>https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cloudflare-access-vs-aws-iam-idc/</guid><description>Đừng cố unify Cloudflare Access và AWS IAM Identity Center. Pattern thực dụng: Okta/Entra → SSO cả hai, SCIM provisioning, per-app policy, audit correlation.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>AWS</category><category>Identity</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>AWS KMS Key Policies: hiểu đúng để không mất quyền truy cập</title><link>https://cloudsecop.net/blog/kms-key-policies-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/kms-key-policies-deep-dive/</guid><description>Cơ chế evaluation của KMS key policy, cross-account access, condition keys, grants, key rotation, production patterns. Kèm JSON policy examples và checklist cho production.</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>KMS</category><category>Encryption</category><category>IAM</category><author>KhaVan</author></item><item><title>GuardDuty auto-remediation: cô lập EC2 và thu hồi IAM</title><link>https://cloudsecop.net/blog/guardduty-auto-remediation/</link><guid isPermaLink="true">https://cloudsecop.net/blog/guardduty-auto-remediation/</guid><description>Pipeline tự động phản ứng sự cố bảo mật với GuardDuty, EventBridge và Lambda: cô lập instance, snapshot forensic, thu hồi credentials, mở rộng multi-account với Organizations.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Automation</category><category>EventBridge</category><author>KhaVan</author></item><item><title>AWS Secrets Manager vs Cloudflare Secrets Store: khi nào dùng cái nào</title><link>https://cloudsecop.net/blog/aws-secrets-manager-vs-cloudflare-secrets/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-secrets-manager-vs-cloudflare-secrets/</guid><description>AWS Secrets Manager $0.40/secret/mo + auto-rotation Lambda vs Cloudflare Secrets Store free trên Workers Paid. Khi nào chọn cái nào, replication pattern.</description><pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloudflare</category><category>Secrets Manager</category><category>Security</category><category>DevOps</category><author>KhaVan</author></item><item><title>Pingora vs AWS ALB/NLB — khi nào self-host reverse proxy thắng</title><link>https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</link><guid isPermaLink="true">https://cloudsecop.net/blog/pingora-vs-aws-alb-nlb/</guid><description>Pingora xử lý 40M+ req/sec ở Cloudflare. Khi nào self-host bằng pingora-core/pingora-proxy thắng AWS ALB $20/tháng + LCU và NLB managed.</description><pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Networking</category><category>Rust</category><category>AWS</category><category>Performance</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS sang GCP: keyless auth</title><link>https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</guid><description>Workload Identity Federation deep dive: vì sao Service Account Key là anti-pattern, luồng token AWS STS → Google STS, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>AWS IAM Access Key rotation: Lambda + Secrets Manager</title><link>https://cloudsecop.net/blog/aws-iam-access-key-auto-rotation/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-iam-access-key-auto-rotation/</guid><description>Một giải pháp AWS-native để rotate, disable và delete IAM access key theo chính sách: đi sâu vào kiến trúc nhiều account, đánh đổi và vận hành thực tế.</description><pubDate>Tue, 31 Dec 2024 00:00:00 GMT</pubDate><category>AWS</category><category>IAM</category><category>Security Automation</category><category>Secrets Manager</category><category>Lambda</category><author>KhaVan</author></item><item><title>Chạy CSPM trên hơn chục AWS Landing Zone</title><link>https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</guid><description>Cách mình thiết kế CSPM engine nội bộ quét song song nhiều AWS Landing Zone bằng Prowler, lưu finding vào D1, artifact vào R2, dashboard duy nhất cho Security Operations.</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>CSPM</category><category>Prowler</category><category>Cloudflare</category><author>KhaVan</author></item></channel></rss>